← Vulnerability feed

Vulnerability record · CVE-2012-1438 · published 21 March 2012

CVE-2012-1438: Comodo antivirus permissions and access controls vulnerability

Comodo · Comodo Antivirus

The Microsoft Office file parser in Comodo Antivirus 7425 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via an Office file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Office parser implementations.

4.3 CVSS 2.0 Medium EPSS 14% · top 3.6% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The Microsoft Office file parser in Comodo Antivirus 7425 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via an Office file with a ustar character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Office parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1438 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6335Sophos anti-virus vulnerabilityMultiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive wit…EPSS 13%9.3CVE-2008-0470Comodo antivirus vulnerabilityA certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.EPSS 31%7.5CVE-2006-0994Sophos anti-virus vulnerabilityMultiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, …EPSS 22%7.5CVE-2005-2768Sophos anti-virus vulnerabilityHeap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote …EPSS 13%7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 63%analysed7.5CVE-2004-0933Archive zip vulnerabilityComputer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content M…EPSS 21%7.5CVE-2004-0934Archive zip vulnerabilityKaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whi…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2012-1438), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.